<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Am Security &#187; summary</title>
	<atom:link href="http://www.iamit.org/blog/tag/summary/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iamit.org/blog</link>
	<description>Security news and research</description>
	<lastBuildDate>Mon, 26 Jul 2010 09:20:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
<cloud domain='www.iamit.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Tying up loose ends before Vegas (scammer closure)</title>
		<link>http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/</link>
		<comments>http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 09:20:36 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[Attack Vector]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[summary]]></category>
		<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=501</guid>
		<description><![CDATA[Instead of updating the post in question (again), I figured I&#8217;ll post all the new info here and call this a wrap. So, we all know about the security scammer now, and the different ways he is working to defraud innocent users and steal their data and money. It has been quite an experience tracking [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/' rel='bookmark' title='Permanent Link: How [not to] scam security people'>How [not to] scam security people</a></li>
<li><a href='http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/' rel='bookmark' title='Permanent Link: The Turkish hack and another case for IL-CERT'>The Turkish hack and another case for IL-CERT</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Instead of updating the <a href="http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/">post in question</a> (again), I figured I&#8217;ll post all the new info here and call this a wrap.</p>
<p>So, we all know about the security scammer now, and the different ways he is working to defraud innocent users and steal their data and money. It has been quite an experience tracking this scam down and getting all the facts right (from the technical aspect of inspecting the keylogger and binaries used to sniff your data, to actually communicating with the scammer and getting his take on things).</p>
<p>Nevertheless, I must say that I appreciate the consistency in which our scammer (I&#8217;ll call him Fadzil Mahfodh as that&#8217;s his real name) has been trying to mask his wrongdoings. From trying to go around the facts and divert us to other software:</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil1.png" rel="lightbox[501]"><img class="size-medium wp-image-502 alignnone" title="fadzil1" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil1-300x57.png" alt="" width="300" height="57" /></a></p>
<p>To &#8220;bragging&#8221; about his skills and the fact that his scripts are &#8220;leet&#8221; enough to get past some people:</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil2.png" rel="lightbox[501]"><img class="size-medium wp-image-503 alignnone" title="fadzil2" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil2-300x79.png" alt="" width="300" height="79" /></a></p>
<p>And finally to the obvious &#8211; throwing a fit and trolling &#8211; initially by threatning to post my picture and CV on adult websites (what would my CV be good for on an adult site anyway??? must be a Malaysian thing <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  ):</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil3.png" rel="lightbox[501]"><img class="size-medium wp-image-504 alignnone" title="fadzil3" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil3-300x39.png" alt="" width="300" height="39" /></a></p>
<p>All of which has been accompanied by adding my picture to his website (wow! I&#8217;m famous now!):</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.54.25-AM.png" rel="lightbox[501]"><img class="size-medium wp-image-505 alignnone" title="Screen shot 2010-07-26 at 11.54.25 AM" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.54.25-AM-300x213.png" alt="" width="300" height="213" /></a></p>
<p>Getting it removed by the Google Blogger DMCA team, opening up a <a href="http://chikiabu.blogspot.com/">new blog site</a> to accompany the specific <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.58.16-AM.png" rel="lightbox[501]"><img class="alignright size-medium wp-image-507" title="Screen shot 2010-07-26 at 11.58.16 AM" src="http://www.iamit.org/blog/wp-content/uploads/2010/07/Screen-shot-2010-07-26-at-11.58.16-AM-181x300.png" alt="" width="181" height="300" /></a>&#8220;hack wpa without a dic&#8221; post along with my picture, and making some cosmetic changes to the site, removing the FBI log (which has been replaced with a larger DHS logo), and adding a disclaimer at his website stating that this is all a mistake, that I have been trying to pressure him into criminal actions, and that he has all our communications logged and will be happy to use it to prosecute. Too bad this has been removed from his site before I had a chance to document it &#8211; but trust me it was there! Pure epicness!</p>
<p>Now, I know &#8211; it&#8217;s not really fair to pick on these guys that hard. That&#8217;s why I&#8217;m leaving this to the Malaysia CERT (as you may have noticed, 1337 Fadzil forgot to proxy his connections to this blog and his IP has been logged on all comments and relevant hits on the site), to figure out how to handle. I truly hope that his suggestion to use the details provided on his paypal account and bank account will actually yield some results, and wish our friend the best of luck in his endeavors in the security business (although I highly doubt he&#8217;ll be at DefCon later this week).</p>
<p>Below are attached some of the additional supporting materials for the sake of fully disclosing all the communications with Fadzil.</p>
<p><a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/fadzil.txt">Apache-access-log_FILTERED</a>, <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/Fadzil-chat.rtf">Fadzil-chat</a>, <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/karma-decoded.sh.txt">karma-decoded.sh</a>, <a href="http://www.iamit.org/blog/wp-content/uploads/2010/07/bg2-decoded.sh.txt">bg2-decoded.sh</a></p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/07/how-not-to-scam-security-people/' rel='bookmark' title='Permanent Link: How [not to] scam security people'>How [not to] scam security people</a></li>
<li><a href='http://www.iamit.org/blog/2010/07/the-turkish-hack-and-another-case-for-il-cert/' rel='bookmark' title='Permanent Link: The Turkish hack and another case for IL-CERT'>The Turkish hack and another case for IL-CERT</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/identity-crisis/' rel='bookmark' title='Permanent Link: Identity crisis'>Identity crisis</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/07/tying-up-loose-ends-before-vegas-scammer-closure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>And the winner for &#8220;top virus&#8221; of 2007 is&#8230;</title>
		<link>http://www.iamit.org/blog/2008/01/and-the-winner-for-top-virus-of-2007-is/</link>
		<comments>http://www.iamit.org/blog/2008/01/and-the-winner-for-top-virus-of-2007-is/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 02:49:23 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Finjan]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[summary]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=34</guid>
		<description><![CDATA[Not a virus. Not even a malware. Neither is the runner up… It&#8217;s the method of how malware is populated. According to a report, the most common malware attack in 2007 is the notorious IFRAME. On our monthly and quarterly reports we provided more in-depth analysis of such top-ranking IFRAME and obfuscated code. In Finjan’s [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2007/06/have-something-to-hide-make-a-lot-of-noise-about-it/' rel='bookmark' title='Permanent Link: Have something to hide? make a lot of noise about it!'>Have something to hide? make a lot of noise about it!</a></li>
<li><a href='http://www.iamit.org/blog/2007/10/iframe-is-a-security-risk/' rel='bookmark' title='Permanent Link: IFRAME is a security risk???'>IFRAME is a security risk???</a></li>
<li><a href='http://www.iamit.org/blog/2007/10/playing-with-obfuscators-teaching-an-old-dog-new-tricks/' rel='bookmark' title='Permanent Link: Playing with obfuscators &#8211; teaching an old dog new tricks&#8230;'>Playing with obfuscators &#8211; teaching an old dog new tricks&#8230;</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Not a virus. Not even a malware. Neither is the runner up… It&#8217;s the method of how malware is populated.</p>
<p>According to <a href="http://www.sophos.com/pressoffice/news/articles/2008/01/toptendec07.html" target="_blank">a report</a>, the most common malware attack in 2007 is the notorious IFRAME.</p>
<p><img class="aligncenter size-full wp-image-308" title="top_virus_2007" src="http://www.iamit.org/blog/wp-content/uploads/2008/01/top_virus_2007.png" alt="top_virus_2007" width="454" height="298" /></p>
<p align="center">
<p>On our <a href="http://www.finjan.com/content.aspx?id=1367">monthly</a> and <a href="http://www.finjan.com/content.aspx?id=827">quarterly</a> reports we provided more in-depth analysis of such top-ranking IFRAME and obfuscated code.<br />
In Finjan’s terminology, the top-ranked virus IFRAME is not a malware or a virus, it&#8217;s more like how criminals are directing users’ browsers to a malware. Interestingly enough – the runner-up is “Mal/ObfJS” – Obfuscated javascript, again no a virus or malware but a simple technique to hide exploits from signature matching inspection.</p>
<p>How come? Well, remember that signature-based solutions are in a dire need to be able to stop the more common techniques employed by attackers (we have actually started to report on them during 2006), since the detection technology is limited in detecting the obfuscation and evasive techniques – typically signaturing the de-obfuscating portions of the script.</p>
<p>This has led to the recent <a href="http://isc.sans.org/diary.html?storyid=3803" target="_blank">reports</a> of <a href="http://isc.sans.org/diary.html?storyid=3797" target="_blank">false-positives</a> by <a href="http://www.kaspersky.com/technews?id=203038717" target="_blank">multiple</a> AV <a href="http://erratasec.blogspot.com/2008/01/wow.html" target="_blank">vendors</a> lately, as active-content is becoming more and more complicated, and the ways to express an action in interpreted code are very complex – meaning that signatures in this realm are almost obsolete (you can see the honorary mention of the “DF” function (Mal/FunDF) in the 10th place, which is a signature on a specific de-obfuscating function – again, no mention of any malicious action taken by it, it’s just that it had it’s 15 minutes of fame when it was used by toolkits to deliver actual malicious code…)</p>
<p>Looking forward to 2008 I really hope that the industry as a whole will not be lagging behind the attack vectors as it did in 2007, and new and improved engines would enable end-users (especially consumers who do not benefit from the more sophisticated solutions offered to enterprises) to have better protection when using the internet.</p>
<p>I know what my new-year resolutions are – do you?</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2007/06/have-something-to-hide-make-a-lot-of-noise-about-it/' rel='bookmark' title='Permanent Link: Have something to hide? make a lot of noise about it!'>Have something to hide? make a lot of noise about it!</a></li>
<li><a href='http://www.iamit.org/blog/2007/10/iframe-is-a-security-risk/' rel='bookmark' title='Permanent Link: IFRAME is a security risk???'>IFRAME is a security risk???</a></li>
<li><a href='http://www.iamit.org/blog/2007/10/playing-with-obfuscators-teaching-an-old-dog-new-tricks/' rel='bookmark' title='Permanent Link: Playing with obfuscators &#8211; teaching an old dog new tricks&#8230;'>Playing with obfuscators &#8211; teaching an old dog new tricks&#8230;</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2008/01/and-the-winner-for-top-virus-of-2007-is/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
